When hit with a cyber-attack, many companies are choosing to remain as shadowy as the clandestine hackers that strike them. More than a year has passed since the Securities and Exchange Commission issued guidance suggesting that publicly traded companies should disclose cyber-security risks and attacks that result in material losses. Yet, many companies remain tight-lipped, […]
Internal Controls
Fostering a Unified, Ethical, and Global Corporate Culture
Building an ethical corporate culture can be daunting under even the best of circumstances. Add to the mix a workforce located in multiple countries, each with its own culture, language, and legal system, and the challenges are magnified. Yet, companies can’t ignore these obstacles, given the increasingly global economy. In 2011, nearly half (46 percent) […]
Codes of Conduct: Values or Principles-Based?
Compliance professionals generally agree that a code of conduct is an essential component to communicating the standards of behavior that a company expects of its employees. But how best to accomplish that goal? Well, that’s a whole other story. Companies tend to break into two camps when it comes to what should be included in […]
COSO’s Take Two on Internal Control Framework Earns Praise
The revised COSO internal control framework is so close to final it’s time for companies to line it up against their present system and see where changes might be in order. โCompanies may consider acting early and updating their processes around internal control in light of the 17 principles,โ says Jennifer Burns, a partner at […]
EEOC Enforcement Plan Signals Shift to Systemic Cases
The Equal Employment Opportunity Commission recently unveiled its revised draft strategic enforcement plan, providing a blueprint of the agency’s highest-priority cases for the next four fiscal years. The revamped strategic enforcement plan (SEP), released last month, builds upon the priorities of the EEOC’s Systemic Task Force, a program adopted in 2006 with the goal of […]
COSO Releases Revised Framework, New Guidance
COSO has published a second draft of its updated internal control framework along with some new companion guidance, looking for fresh comments on whether the entire package meets the mark in updating the framework that most public companies use to achieve compliance with internal control reporting requirements under Sarbanes-Oxley. The Committee of Sponsoring Organizations of […]
Building Regulatory Intelligence
In the time it takes you to read this arยญticle your business has changed. The economic environment has changed, your employees have changed, and there are constant changes to technology, comยญpetition, and processes. Business drifts in a sea of change. One particular area of change that bears down on the organizaยญtion is the siege of […]
The Evolving Role of Internal Audit
A confluence of increased regulation, intense focus on corruption, and heightened scrutiny of risk management is changing the role of the internal auditor. From evaluating and mitigating fraud and corruption risks, to improving IT and business operations, the internal audit function must evolve to meet the expanding needs of management and other stakeholdersโso said industry […]
Why Do Policies Matter?
From time to time, to my surprise, I still hear people asking why policies matter. After all, they argue, aren’t the laws and regulations we have to follow enough guidance? Beyond those requirements, can’t we let managers decide how to run their own operations and have case-by-case flexibility? Don’t policies create liability when they aren’t […]
State of Compliance 2012
The good news for compliance programs is that many are finally getting the added resources they need to get the job done. The challenge, however, is how to best leverage staff and technology to keep pace with the regulatory onslaught they face and the increasingly complex, specialized issues they must handle. Those insights were among […]


